Skip to main content

Public exposure intelligence

Public intelligence, handled carefully

Intelis contributes public exposure and identity intelligence, covering organisational email exposure indicators, lookalike domains and brand impersonation signals.

The section this supports

Exposure findings appear in a report subsection called Identity & Breach Exposure, carrying the attribution “Intelligence provided by Intelis”. It is a defined part of the report rather than a claim about the whole service.

The category

Why this sits inside a website assessment at all

Search intelligence is about how an organisation is understood. Exposure intelligence is about how it can be impersonated. They are closer than they look: both concern the public information that accumulates around a business, and both are usually the responsibility of nobody in particular.

The practical connection is that the same organisation that has never enforced a DMARC policy is frequently the one with a lookalike domain registered six months ago and three published staff addresses in an old breach corpus. Individually each is minor. Together they describe a business that would be straightforward to impersonate convincingly, which is what invoice fraud requires.

None of that means an organisation is under attack. It means the preconditions are in place, and knowing that is worth something — provided it is communicated without theatre.

Coverage

What exposure intelligence covers

Public signals only. Nothing here requires access to your systems, and nothing here constitutes evidence about them.

Identity

  • Organisational email addresses published on the website itself
  • Common address patterns a business uses
  • Known third-party breach associations, where verified access permits
  • Counts and masked samples rather than lists

Impersonation

  • Lookalike domain indicators
  • Brand impersonation signals
  • Certificate history entries for the domain
  • Public subdomain indicators

Public footprint

  • Publicly reachable documents and their metadata
  • General exposure signals from public sources
  • Indicators requiring verification before detail is shown

Handling

What is never published, and why

A tool that displays an organisation’s staff addresses, breach records or internal asset names to whoever typed the domain into a form is not providing intelligence. It is providing reconnaissance, and it is doing so to an audience it has not identified.

So the public output is deliberately thin: counts, categories and masked samples such as j***@example.com. Enough to establish that something exists and warrants attention. Not enough to be useful to anybody building a target list.

Detail beyond that requires domain verification and, where a third-party data source is involved, appropriate authorised access to it. That threshold exists to protect the people whose addresses are involved, who did not ask to be part of anyone’s assessment.

Never shown publicly

  • Complete employee email addresses
  • Passwords or credential material of any kind
  • Raw breach records
  • Stealer-log or infostealer material
  • Exact internal asset names or addresses
  • Findings attributed to named individuals

Example finding

How exposure is worded

Specific about what was observed, explicit about what it does not prove, and free of the language that turns a manageable issue into a crisis.

This is an illustration of the report format rather than a result from a real assessment.

Moderate

Organisational Addresses Associated With Third-Party Incidents

What we found
Three addresses using this domain's pattern appear in association with two known third-party incidents. Samples are masked. No assessment has been made of whether these addresses remain active or whether any associated credential is still in use.
Why it matters
An address appearing in a third-party breach indicates that a service the address was registered with was compromised. It is not evidence that this organisation's systems were affected. Its practical significance is that these addresses are more likely to be targeted, and that any credential reused across services should be treated as known.
General direction
Confirm which of these addresses are still active, ensure multi-factor authentication is enforced on the accounts they access, and treat any password reused between a personal service and a business system as compromised. This is a hygiene exercise rather than an incident response.
How IXSEO can help
Verified exposure review. Intelligence provided by Intelis.

What verification changes, and what it does not

Verifying control of a domain expands what can be shown to you about that domain. Detailed organisational exposure findings, affected addresses in fuller form and the evidence behind them become available, because at that point they are being shown to somebody with a demonstrated relationship to the domain rather than to an anonymous visitor.

It changes nothing about authority. Verification proves control of an approved domain resource — an administrative mailbox, a DNS record, a verification file. It does not establish that the person holding that control is authorised to commission testing of the organisation’s infrastructure, and it is never treated as though it does.

Common questions

Does an exposure finding mean we have been hacked?
No, and this is the single most important thing to understand about the category. A company address appearing in a third-party breach means a service that address was registered with was breached. It says something about that service, not about your systems. Presenting it as evidence of compromise is alarmist, common, and wrong — which is precisely why the wording here is careful.
Why can I not see the actual email addresses?
Because publishing a list of an organisation's staff addresses to whoever typed the domain in would be a straightforward gift to anyone assembling a phishing campaign. The public report gives counts and masked samples. Detailed organisational results require domain verification and an appropriate data source, which is a deliberate constraint rather than an upsell.
Is IXSEO 'powered by Intelis'?
No. Intelis contributes intelligence to the exposure sections of a report, and the attribution appears there. It is not a general provider to the service, and describing it as one would misrepresent both organisations. The wording used throughout is 'Intelligence provided by Intelis' on the relevant sections only.
What is a lookalike domain indicator?
A domain registered to closely resemble yours — a transposed character, a different top-level domain, an inserted hyphen. Most are registered defensively or by domain speculators and are entirely harmless. A small number are used for invoice fraud, where an email from a domain differing by one letter is remarkably effective. The indicator flags similarity; establishing intent requires looking at what the domain actually does.
Can you monitor this continuously?
Exposure indicators are point-in-time within an assessment. Continuous monitoring is a different service with different data handling and different obligations, and it is not something offered through a website analysis. Where an organisation needs it, we would rather say so and discuss it properly than imply a snapshot provides it.

Intelligence provided by Intelis

Intelis contributes intelligence to the exposure sections of an IXSEO report. No claim is made that the two share a legal entity, and IXSEO is not described as being powered by Intelis.

Exposure is one module among eleven

It is selected rather than assumed, because plenty of organisations have a more pressing question about how they are found in the first place.

IXSEO performs passive public analysis unless a separate authorised engagement has been agreed.